Vulnerabilities
Summary — last 7 days
New vulnerabilities3,045▲ 455 vs. last week
Critical / high1,424▲ 188 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)389▲ 174 vs. last week
44 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 0.17% | — | Paloaltonetworks Idira Privilege Cloud Connector | 6/12/2026 | 6/23/2026 | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | |
| Deferred | Low (3.5) | 0.46% | — | SAP Cloud ConnectorAI | 8/12/2025 | 6/17/2026 | Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful exploit could lead to reduced performance, hence a low-impact on availability of the service.… | |
| Deferred | Critical (9.3) | 0.56% | — | Tigo Energy Cloud Connect AdvancedAI | 8/6/2025 | 6/17/2026 | Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar energy production, and… | |
| Deferred | Medium (4.2) | 0.37% | — | Delimited File Connector Cloud ConnectorAI | 5/15/2024 | 6/17/2026 | A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ attribute, which in turn allowed the user to access files uploaded for other sources. | |
| Deferred | High (8.2) | 0.26% | — | Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+15 | 5/14/2024 | 6/17/2026 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software… | |
| Modified | High (7.4) | 0.54% | — | SAP Cloud Connector | 2/13/2024 | 6/17/2026 | Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system. | |
| Modified | Low (3.5) | 0.27% | — | SAP Cloud Connector | 12/12/2023 | 6/17/2026 | SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confidentiality or Integrity of the application. | |
| Modified | High (8.7) | 1.1% | — | Siemens Simatic Cloud Connect 7 Cc712 FirmwareSiemens Simatic Cloud Connect 7 Cc716 FirmwareSiemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF Firmware+74 | 9/12/2023 | 6/17/2026 | The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially… | |
| Analyzed | Critical (10) | 100% | ⚠ Active exploitation | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 12/10/2021 | 8/11/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modified | Critical (9.1) | 0.56% | — | SAP Cloud Connector | 9/15/2021 | 6/17/2026 | Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate. | |
| Modified | Medium (4.8) | 0.46% | — | SAP Cloud Connector | 9/15/2021 | 6/17/2026 | SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting. | |
| Modified | Medium (6.8) | 0.54% | — | SAP Cloud Connector | 9/15/2021 | 6/17/2026 | SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution. | |
| Modified | High (7.5) | 1.2% | — | SAP Cloud Connector | 9/15/2021 | 6/17/2026 | SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories. | |
| Modified | Low (3.5) | 0.96% | — | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+12 | 6/22/2021 | 6/17/2026 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated.… | |
| Modified | High (7.5) | 1.0% | — | Citrix Cloud Connector | 6/16/2021 | 6/17/2026 | Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of… | |
| Modified | High (7.5) | 54% | — | Eclipse JettyOracle Autovue FOR Agile Product Lifecycle ManagementOracle Communications Cloud Native Core PolicyOracle Communications Element Manager+17 | 4/1/2021 | 6/17/2026 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | |
| Modified | Medium (5.3) | 82% | — | Eclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+13 | 4/1/2021 | 6/17/2026 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive… | |
| Modified | Low (2.7) | 4.2% | — | Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+19 | 4/1/2021 | 6/17/2026 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. | |
| Modified | Medium (5.9) | 64% | — | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 3/25/2021 | 6/17/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Analyzed | Medium (5.3) | 3.2% | — | Oracle OpenjdkOracle GraalvmOracle JDKOracle JRE+15 | 10/21/2020 | 6/17/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Analyzed | Low (3.1) | 2.7% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 10/21/2020 | 6/17/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analyzed | Low (3.7) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 10/21/2020 | 6/17/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analyzed | Low (3.1) | 2.5% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+14 | 10/21/2020 | 6/17/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analyzed | Medium (4.2) | 2.2% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 10/21/2020 | 6/17/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Analyzed | Low (3.7) | 2.3% | — | Oracle OpenjdkOracle JDKOracle JRENetapp 7-mode Transition Tool+13 | 10/21/2020 | 6/17/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… |